CPS 230 came into force on 1 July 2025 for every APRA-regulated entity: banks, insurers and superannuation trustees alike. The transitional relief that let pre-existing service provider contracts wait for their next renewal ran out, at the latest, in July 2026. And APRA’s April observations on implementation made its view plain: governance is not keeping pace with adoption. This is no longer a future deadline. It is the supervision you are under right now.
Most of the commentary treats CPS 230 as a business continuity exercise. The sharper question for anyone running credit decisioning, claims automation or customer engagement systems is simpler: if a system makes customer decisions and the decisions stop, is that a disruption to a critical operation? Increasingly, the answer is yes, and that changes how you buy, run and evidence decisioning.
What does CPS 230 actually require?
Four things matter here. You must identify your critical operations, the processes whose disruption would cause material harm to customers or the financial system. You must set board-approved tolerance levels for each: how long it can be down, how much data loss is acceptable, and prove you can operate within them under severe scenarios. You must identify and manage material service providers, with due diligence, a register lodged with APRA, and credible exit plans. And when things go wrong, the clocks are short: APRA must be notified within 24 hours of a disruption that breaches a tolerance level, and within 72 hours of an operational risk incident with likely material impact.
Is customer decisioning a critical operation?
APRA names the obvious candidates: payments, deposit-taking, claims processing, fund administration. Decisioning systems rarely appear on that list by name, but they sit inside almost everything on it. Claims processing is a chain of decisions. Origination is a chain of decisions. Hardship treatment, fraud interdiction and collections are decisions with statutory consequences. If the decision engine stalls, the critical operation it serves stalls with it, or worse, keeps running while making decisions nobody can stand behind.
That second failure mode deserves more attention than it gets. An outage is visible and bounded. A decisioning system that degrades quietly, approving what it should refer, mispricing risk, mishandling a hardship flag, can breach your tolerance for harm without ever tripping an availability alert. Tolerance levels for decisioning need to cover quality, not just uptime.
Your decision engine’s vendor is probably a material service provider
If a third party hosts or operates the system your critical operations depend on, CPS 230 pulls that relationship into scope: due diligence before you sign, ongoing monitoring, inclusion in the register, and an exit strategy that is more than a clause. With the contract transition period behind us, “we inherited this arrangement” no longer answers the question.
This is worth asking of any decisioning vendor, ours included. Can they show you the audit trail their system keeps? Can you get your decision history and policy configuration out, in usable form, if you leave? Does a degraded mode exist, and has anyone tested it? Vendors built for regulated environments answer these quickly; vendors retrofitted for them change the subject.
What to do now
- Map every automated customer decision to the critical operation it serves. The unmapped ones are the finding an APRA review will write up.
- Extend tolerance levels beyond availability: define what unacceptable decision quality looks like and how you would detect it.
- Check your material service provider register against reality. A decisioning SaaS that quietly became load-bearing since the register was lodged is exactly the gap the standard targets.
- Rehearse the 24-hour clock. When a tolerance is breached, the evidence, the decision log and the accountable owner all need to be findable in hours, not assembled in a war room.
The pattern across jurisdictions is consistent: regulators are converting principles into evidence they can inspect, the same shift we covered for Singapore’s FEAT regime. Decisioning that is explainable, auditable and recoverable by design, the way we built CxOS, turns that inspection from a scramble into a query. For where this lands across the sector, see our work in banking and finance.